Sign in

Adam Faris

@af9.us
99 followers 271 following 156 posts

Writing about systems and storage at amf3.github.io

PostsRepliesMedia
Adam Faris @af9.us · 20/09/2026
I'm building a Samba container but muscle memory keeps typing Samza. It's been two years since I've worked with Samza ... geesh!
001
Adam Faris @af9.us · 19/09/2026
I started a new series for self hosting services on public networks. How network segmentation and firewall rules can limit network traffic to what's needed. The main page links to the first section discussing L2 networks. #homelab #selfhosting amf3.github.io/articles/net...
amf3.github.io
Self Hosting Publicly Facing Services
Understanding Virtual Networking and Segmentation: A Three Part Series
100
Reposted by Adam Faris
Alex Edwards @ajmedwards.bsky.social · 18/09/2026
Both my books, Let's Go and Let's Go Further, are now fully updated for Go 1.27 - including coverage of json/v2 in Let's Go Further & optional dark mode in the HTML versions. If you're interested in building web apps or APIs with Go, it's a great time to check them out! www.alexedwards.net/books
alexedwards.net
Books - Alex Edwards
061
Adam Faris @af9.us · 01/09/2026
Wow. I wonder what kind of UEFI mischief we can get into? 😃
100
Adam Faris @af9.us · 30/08/2026
I finally figured out how to match veth endpoints on the host to #Docker containers on #Linux by mapping network namespaces. Here's a gist if you need to figure out which veth device to run tcpdump against. gist.github.com/amf3/ca6b910...
gist.github.com
How do I map a VETH pair to a Docker Container?
How do I map a VETH pair to a Docker Container? GitHub Gist: instantly share code, notes, and snippets.
120
Adam Faris @af9.us · 29/08/2026
A fun find. multikernel.io has created a multi-kernel kernel. A spawn kernel off lines hardware devices (CPU, MEM, PCIE) and kexe’s a child kernel to run on the offline resources. Essentially a HW partitioner like IBM Z’s LPAR but for x86. Not sure I'll get to it, but it looks interesting.
multikernel.io
Multikernel Technologies - Split-Kernel Architecture for Linux
Multikernel turns servers you own and VMs you rent into a private cloud: bare-metal performance, kernel-level isolation, no hypervisor, no virtualization tax.
000
Adam Faris @af9.us · 26/08/2026
I was excited to try #QEMU 11.1.0 on #macOS after learning the hvf accelerator supports nested virtualization. I tested a #Multipass image on M2 silicon and initially thought the Ubuntu image didn’t have #KVM support. It turns out you need M3 or newer Apple Silicon for nested virt. Womp-womp … 🪊
developer.apple.com
isNestedVirtualizationSupported | Apple Developer Documentation
A Boolean value that describes whether the platform configuration supports nested virtualization.
000
Adam Faris @af9.us · 22/08/2026
I’m quietly publishing #OCI container images in my corner of the Internet.: Busybox, Unbound DNS, Python 3.14. I’ve used the latter two to build a DNS based ad blocker that I run at home with #Docker.
100
Adam Faris @af9.us · 11/07/2026
I discovered #docker buildx can bind mount files from one build stage into another. This simplifies #distroless container image modifications when combined with Busybox. Instead of writing a new post, I updated my existing tips and tricks with Busybox. amf3.github.io/articles/vir...
amf3.github.io
No Shell in Your Container? No Problem
Injecting Busybox into Minimal/Distroless Containers
020
Adam Faris @af9.us · 29/06/2026
I like educational posts, but this includes the challenge of "how fast could I answer"? For just_enough minimal containers, I'd say 3-5 minutes. Long enough for me to either extract the SBOM from the container image or to click the #buildroot project link on gitlab. github.com/amf3/just_en...
Screen shot showing upstream busybox and ca-certificate sources for the just_enough busybox container image.
020
Adam Faris @af9.us · 29/06/2026
Pi-Hole felt too heavy. I wanted a local recursive resolver that supports ad-lists, split horizon records, and reporting. The final runtime is a #distroless Unbound DNS container. The config generator can be found here: github.com/amf3/adlist_... #selfhosted #docker
Screen shot showing a report duplicate entries when combining ad block-list and the resolver blocking DNS requests for advertisement domains.
030
Adam Faris @af9.us · 20/06/2026
FYI: Fees for the California Parks Historian Passport pass have been waived until July 6th. www.gov.ca.gov/2026/06/17/g...
gov.ca.gov
Governor Newsom announces special free pass to California’s state historic parks in honor of Juneteenth and America’s 250th anniversary | Governor of California
010
Adam Faris @af9.us · 17/06/2026
I didn't know that #Golang had these compile options for AVX instructions. Useful for CPUs made after 2011. lemire.me/blog/2026/06...
lemire.me
How much do amd64 microarchitecture levels help in Go?
Our 64-bit Intel and AMD processors have evolved over decades. When you compile a Go program for a 64-bit Intel or AMD processor, the compiler targets, by default, a nearly 20-year-old instruction set...
041
Adam Faris @af9.us · 16/06/2026
Lessons from my software supply chain adventures. * Control the build pipeline, control the artifact. * Declaritive image contents are the goal. Small image sizes are a byproduct. * Stop waiting for vendor patches. Update the base git hash & rebuild. Resulting in a 51MB #Python flask app.
Screen shot of a simple hello-world app running inside a 51MB flask container.
111
Adam Faris @af9.us · 02/06/2026
I just found out BusyBox can self generate all its applet links. This could be handy if you want to inject a shell into a #distroless or minimal container image. "/bin/busybox --install -s /bin" Screenshot is an example Dockerfile showing how this is done.
Example Docker file showing how BusyBox can be injected into a shell-less container image.
120
Adam Faris @af9.us · 15/05/2026
I'm exploring self-hosted software supply chains and building appliance style containers from #buildroot generated binaries. Today I got OCI image attestation working on an Unbound DNS container build. Seeing provenance attached from build system to container image feels like a big milestone.
Screenshot showing attestation works against my diy unbound dns container.
110
Adam Faris @af9.us · 01/05/2026
‪I wrote a runc wrapper that uses bpftrace to log openat system calls made by an application inside a Docker container. It turns out static analysis misses a lot. amf3.github.io/articles/vir...
amf3.github.io
Container Image Validation
Ensuring containers have what they need. Nothing more, nothing less.
000
Adam Faris @af9.us · 18/04/2026
Why does a Python container need a Perl interpreter? It's not wrong but it's unexplained. Here's a demo showing how a manifest is applied to a scratch image so every file exists with intent. No need for a base image or removal of existing packages. amf3.github.io/articles/vir...
amf3.github.io
Declarative Builds
Demonstrating an Opinionated Build Process for Container Images
111
Adam Faris @af9.us · 13/04/2026
I finally wrote this up: amf3.github.io/articles/vir... What I found interesting wasn't what's in the base image but how much content is present without intent. Looking forward I'm planning for better declarative builds with a new approach in github.com/amf3/just_en...
amf3.github.io
Hidden Systems in Base Images
You're not choosing an image. You're inheriting a system.
000
Adam Faris @af9.us · 09/03/2026
I'm going to drop this here and see who notices. 👀 Yes it's related to a new article I'm writing. No it doesn't need to be this way.
A Docker command demonstrating the official python container image ships with Perl.
001
Adam Faris @af9.us · 28/02/2026
Nice. I just noticed the #zrepl project updated their Go dependencies in the recent 0.7.0 release. Tooling with earlier versions was getting long in the tooth. #zfs zrepl.github.io/changelog.html
zrepl.github.io
Changelog — zrepl latest documentation
000
Adam Faris @af9.us · 24/02/2026
If you're tired of the "Docker vs Podman" marketing noise, it's time to look at the OCI spec under the hood. I built an image manually with just tar and sha256sum to prove a point. amf3.github.io/articles/vir... #OCI #Containers #DevOps #Hacking #Docker #Podman
amf3.github.io
Open Container Image Format
From Local TAR file to Open Container Image
000
Adam Faris @af9.us · 07/02/2026
Apparently running “apt autoremove” on Ubuntu 25.10 can remove netplan. Without netplan, networking does not survive the reboot, so fun times. At least I still remember how to bring up an interface manually.
010
Adam Faris @af9.us · 04/02/2026
To make CoreDNS recursively resolve addresses I need to link and compile against libunbound? coredns.io/manual/setup... Then why not run unbound? I must be missing something.
coredns.io
CoreDNS: DNS and Service Discovery
Setups Here you can find a bunch of configurations for CoreDNS. All setups are done assuming you are not the root user and hence can’t start listening on port 53. We will use port 1053 instead, using ...
110
Adam Faris @af9.us · 03/02/2026
I just discovered a-Shell for IOS. It’s like reliving the coLinux on WindowsXP days. I can write markdown in Textastic and use a-Shell to push markdown changes to git repos or even running code. 🤯 holzschu.github.io/a-Shell_iOS/
holzschu.github.io
a-Shell
A text-based user interface for a screen-based platform
000
Adam Faris @af9.us · 01/02/2026
I finally found the feature that has me wanting to switch from Make to Just. Just has command line argument support. just.systems/man/en/setti...
just.systems
Setting Variables from the Command Line - Just Programmer's Manual
000
Adam Faris @af9.us · 24/01/2026
Huh. #podman has a rest API with coarse grained access like #docker. If I can read the Podman socket I can dump secrets within the container. I know the API is disabled by default, but enabling it seems to have similar risk as rootless Docker. I never stop being amazed by marketing.
010
Adam Faris @af9.us · 19/01/2026
I was checking backlinks and realized I ended up on Hacker News. news.ycombinator.com/item?id=4656... I mean it's not front page content but baby steps right? 😃
news.ycombinator.com
Docker Socket Myths | Hacker News
010
Adam Faris @af9.us · 09/01/2026
I wrote a new #docker post on why mounting /var/run/docker.sock with the :ro option doesn’t do what people thinks it does. It walks through Unix sockets, the Docker API, why “read-only” fails, and what socket proxies actually provide.

amf3.github.io/articles/vir...
amf3.github.io
Docker Socket Myths
Making Read Only Access Safer
132
Adam Faris @af9.us · 07/01/2026
I learned Docker Engine exposes a prometheus compatible /metrics endpoint. It looks like I can stop using cAdvisor, meaning one less container with access to docker.sock. #docker docs.docker.com/engine/daemo...
docs.docker.com
Collect Docker metrics with Prometheus
Collecting Docker metrics with Prometheus
100
Adam Faris @af9.us · 19/12/2025
New post: Why a Two-Node Docker Swarm w/ ZFS Snapshots Is Enough This isn't about defending Swarm, it's about designing systems with clear failure modes and using storage that doesn't pretend to scale magically #homelab This makes 12 posts in 12 months. 2025 goal met amf3.github.io/articles/arc...
amf3.github.io
Decoupling Compute and Storage
Why a Two-Node Docker Swarm with ZFS Snapshots Is Enough
010
Adam Faris @af9.us · 07/12/2025
Neat, a SSO (single sign-on) middleware that supports OpenID on the frontend and simple HTTP auth with backend apps. This might be what I need for self-hosted services at home. 😀 www.authelia.com
authelia.com
Authelia
Authelia is an open-source authentication and authorization server and portal fulfilling the identity and access management (IAM) role of information security in providing multi-factor authentication ...
000
Adam Faris @af9.us · 02/12/2025
This is fun and shows which topics I discussed throughout the year. My most-used words in 2025 were: 1. "docker" (12×) 2. "plugin" (11×) 3. "cloudinit" (11×) 4. "router" (8×) 5. "qemu" (8×) See which words you used the most here: anisota.net/harvest
anisota.net
Anisota's Annual Bluesky Harvest 2025
A recap of your year on Bluesky. Discover patterns, connections, and insights from your journey in the ATmosphere.
000
Adam Faris @af9.us · 02/12/2025
Will I ever settle on a storage format when writing this app? So far its been SQLite -> Parquet -> NDJSON. I find the JSON part boring. No compression and is it any better than CSV when not using nested fields? Now I'm tempted to try Protobuf to get the compression that I likely don't need.
010
Adam Faris @af9.us · 30/11/2025
I use git submodules to pin the Papermod theme version used by my blog. Tonight I realized I can pin the Hugo web framework by using go modules. The pinned Hugo version is ran with "go tool Hugo". One of those things that became obvious to me once it was obvious. Now for some CI pipeline updates 😐
workflow for using go modules with Hugo generated websites.
020
Adam Faris @af9.us · 25/11/2025
Nice summary of past AWS re:Invent videos on how S3 works behind the scenes. bigdata.2minutestreaming.com/p/how-aws-s3...
bigdata.2minutestreaming.com
how AWS S3 serves 1 petabyte per second on top of slow HDDs
Learn how Amazon built the backbone of the modern web that scales to 1 PB/s and 150M QPS on commodity hard drives
010
Adam Faris @af9.us · 19/11/2025
Do you ever have those moments of running across a fun article, only to realize it was posted on hacker news two months ago? Me, this morning. 🤦‍♂️ bogdanthegeek.github.io/blog/project...
bogdanthegeek.github.io
Hosting a WebSite on a Disposable Vape
Someone's trash is another person's web server.
000
Adam Faris @af9.us · 19/11/2025
I tasted the forbidden fruit. Running my home router inside a VM. It's delicious. #Mikrotik CHR, #QEMU, PCI passthrough, qcow2 snapshots, full reproducibility. Easy rollback. Manage networks like software projects. Here's how I built it: amf3.github.io/articles/vir...
amf3.github.io
Uh-oh. Is the router down?
Easy roll back by managing home networks like a software project
000
Adam Faris @af9.us · 12/11/2025
Is it really only two people who are behind distributing PCI tuples which identify PCI devices on #Linux? Values are distributed in the pci.ids file, used by the kernel and apps like lspci. pci-ids.ucw.cz How does one even land that kind of gig? Yet another moment where my brain says 🤯.
pci-ids.ucw.cz
The PCI ID Repository
000
Adam Faris @af9.us · 04/11/2025
TIL Go quietly fixed sharing behavior with for loop variables being used by goroutines. Previous to Go 1.22 each goroutine reused the same loop variable. Now each iteration gets its own copy. No more i=5 five times. 🤭 This explains why one might find i := i in older code, a work around. #golang
Code behavior output showing the issue in old go compilers and newer versions.
230
Adam Faris @af9.us · 06/10/2025
In the spirit of writing more, here's a post on how I build Go CLIs with urfave/cli, how it keeps help and actions coupled with options, and why I'll use it with future projects. amf3.github.io/articles/cod... #golang #cli
amf3.github.io
Go CLIs: Creating Subcommands and Flags
Using urfave/cli to create polished CLI applications
041
Adam Faris @af9.us · 29/09/2025
Speaking of GC, there's a thread on r/golang that discusses the new experimental Green Tea GC in Go 1.25. Testing shows its not better but it's not worse. www.dolthub.com/blog/2025-09...
dolthub.com
We tried Go's experimental Green Tea garbage collector and it didn't help performance
Go 1.25 includes support for an experimental new garbage collector called Green Tea. We tried it out with Dolt's main performance benchmarks and summarize what difference it made (not much).
030
Adam Faris @af9.us · 25/09/2025
What happens when @birdsoftheworld.bsky.social combines machine learning with a phone? You get a bird ID app that uses bird calls to ID birds. Think Pokémon Go but with real animals. merlin.allaboutbirds.org
merlin.allaboutbirds.org
Merlin Bird ID - Home
Identify Bird Songs and Calls Sound ID listens to the birds around you and shows real-time suggestions for who’s singing. Compare your recording to the songs and calls in Merlin to confirm what you...
130
Adam Faris @af9.us · 11/09/2025
With a QEMU article stalled at 80% complete and a tiny utility project waiting to be published to github, I should probably pay attention to this advice.
040
Adam Faris @af9.us · 11/09/2025
Interesting. QEMU 10.1 supports WASM and can run inside a browser. 🤔 wiki.qemu.org/ChangeLog/10.1
wiki.qemu.org
ChangeLog/10.1 - QEMU
0136
Adam Faris @af9.us · 05/09/2025
I’m feeling out of the loop. I started with MD5 checksums to find duplicate files in local storage. Then I read modern CPUs have instruction sets for SHA256. Oh but there's also xxhash which is even faster at checksums.😕 #golang output shows md5 is 3x slower than sha256 and 5x slower than xxhash
161
Adam Faris @af9.us · 29/08/2025
I like this #golang comparison of different SQLite drivers. They include test environment specifics, which allows me to replicate the findings. github.com/cvilsmeier/g... Without specifics I wonder if the results are valid. Something to keep in mind for the next Product A is better than B post.
github.com
GitHub - cvilsmeier/go-sqlite-bench: Benchmarks for Golang SQLite Drivers
Benchmarks for Golang SQLite Drivers. Contribute to cvilsmeier/go-sqlite-bench development by creating an account on GitHub.
010
Reposted by Adam Faris
Chris @chris.blue · 25/08/2025
SlateDB Go bindings! github.com/slatedb/slat...
github.com
First-pass Go binding for SlateDB by CurryFishBalls9527 · Pull Request #691 · slatedb/slatedb
It's very basic and I'm not very familiar with gobindings & rust, but I was able to get basic stuff working. Hope it helps!
011
Adam Faris @af9.us · 06/08/2025
I like this post explaining how file systems can be implemented with a key value store. blog.vmsplice.net/2024/01/key-...
blog.vmsplice.net
Key-Value Stores: The Foundation of File Systems and Databases
File systems and relational databases are like cousins. They share more than is apparent at first glance. It's not immediately obvious t...
120
Adam Faris @af9.us · 02/08/2025
I’ve been quiet lately while looking into a bufferbloat issue with my home internet. Bufferbloat is latency caused when a router buffers too many packets and can impact games and video calls.
100